CVE-2021-26119

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
5
MEDIUM
Affected
1
PROJECT

Description

Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic.
GitHubGitHub
2.35K